Impact
Google Chrome for Android before version 150.0.7871.47 contains a flaw where uninitialized memory can be read from the UI layer. The issue arises from a use of uninitialized variables, identified by CWE-457. A remote attacker who has already compromised the renderer process can craft an HTML page that triggers this read, enabling the leaking of potentially sensitive data stored in process memory.
Affected Systems
The vulnerability affects Google Chrome on Android devices running any version prior to 150.0.7871.47. Based on the description, users on the stable channel who have not yet installed the update are potentially affected until they apply the new release.
Risk and Exploitability
The CVE is assigned a medium severity rating. The CVSS score of 5.3 confirms this classification, and the vulnerability is not listed in the CISA KEV catalog. No EPSS score is available, indicating limited observed exploitation. However, the flaw requires the attacker to have already compromised the renderer process; if that condition is met, the attacker can exfiltrate data via a crafted HTML page. The overall risk is moderate due to the prerequisite of a renderer compromise and the current lack of widespread attacks.
OpenCVE Enrichment
Debian DLA
Debian DSA